Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2021-44868 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2021-39153 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-38153 Vulnerability in maven package org.apache.kafka:kafka-clients
CVE-2022-25927 Vulnerability in maven package org.webjars.bowergithub.faisalman:ua-parser-js
CVE-2018-14042 Vulnerability in maven package org.webjars.npm:bootstrap-sass